Skip to content

hftools v0.12.0

Choose a tag to compare

@ziozzang ziozzang released this 23 Jul 12:47
· 5 commits to main since this release

Signing identity and trusted keys

Provenance signing now has a persistent per-user identity, so sign and verify-sig no longer require juggling PEM key paths, and a recipient can pin a signer by name.

  • ~/.hftools home store (override with $HFTOOLS_HOME): an ed25519 private key (signing.key, mode 0600), its public key (signing.pub), and a config.yaml holding the signer label and a trusted_keys registry. Still zero external dependencies — config.yaml uses a small built-in YAML reader.
  • sign with no --key uses the home identity, creating it (key + config.yaml) on first run, and defaults the signer label from config.
  • verify-sig auto-recognizes a signer whose key you have trusted (reports trusted key: NAME); --pubkey now also accepts a trusted name. It always prints the key's SHA-256 fingerprint, and when the key is unpinned/untrusted it suggests the key trust command.
  • New key command: init, show, export, trust, untrust, list, path.
# Signer — first sign creates ~/.hftools automatically:
hftools sign --output ./owner_model --signer you@example.com
hftools key export --out mykey.pem            # public key to distribute

# Recipient — trust the signer's key once, then verify:
hftools key trust alice mykey.pem
hftools verify-sig --output ./owner_model     # auto-recognizes the trusted key

Hashing proves a download is intact; a trusted signature proves who produced it — useful across an air gap.

Static binaries for macOS, Windows, and Linux on ARM64 and x86-64. Verify a download against SHA256SUMS.